Polymarket Commits to Full Restitution Following Frontend Security Breach
Polymarket, a leading prediction market platform, recently experienced a sophisticated phishing attack triggered by a compromise in its frontend infrastructure. The incident, which occurred on June 25, led to the theft of millions of dollars after a malicious script was injected into the site through a third-party vendor dependency. Despite the breach, the platform has reassured its community by pledging to fully reimburse every user impacted by the exploit.
A Third-Party Supply Chain Attack
The vulnerability originated from a compromised third-party vendor rather than a flaw within Polymarket’s core smart contracts. Attackers managed to inject a malicious script into the platform’s user interface, exposing users who interacted with the site during a specific window of time. Polymarket acted swiftly to identify the compromised dependency, remove it from their systems, and contain the incident to prevent further damage. While the identity of the vendor remains undisclosed, the platform emphasized that the underlying blockchain architecture remained secure throughout the event.
Financial Impact and Recovery Efforts
Blockchain security researchers, including PeckShield, estimate that the phishing campaign successfully drained approximately $3 million in PUSD from over 11 victim wallets. The stolen assets were subsequently bridged from the Polygon network to Ethereum and converted into nearly 1,893 ETH to obscure the paper trail. In a proactive move to maintain user trust, Polymarket announced it is directly contacting affected individuals to facilitate full refunds for their losses. The company is currently conducting a thorough investigation and has promised a detailed postmortem as it works toward a complete resolution of the incident.